SOC analyst career path: moving to GRC and beyond
Most analysts leave L1 within a few years, either up into deeper SOC work or sideways into a specialty. GRC is one of the most common moves, because the SOC already taught you how controls fail in real life. It is one path among several, and the right one depends on which part of the queue you actually enjoy.
Below are the moves SOC analysts make most often, what each one asks for, and a first step you could take this week. If you are not sure which one fits, tell Carmen what you do now and which tickets you secretly like.
Talk to Carmen
Your AI career coach
Say it the way you’d say it to a friend. Carmen will ask what she needs to know.
Where SOC analysts move next
GRC analyst
Maps controls to frameworks like NIST CSF, ISO 27001 or SOC 2, runs risk assessments, and gathers audit evidence. Suits analysts who write clear tickets and like knowing why a control exists. Less on-call, more meetings and documents.
- What it takes
- Framework knowledge matters more than a certification to start. CISA later requires five years of information systems audit, control or security experience within the prior ten years, per ISACA.
- First step
- Pick one control your SOC monitors, such as MFA or logging, and write up how you would prove to an auditor that it works.
Incident responder
Takes over when an alert turns into a real incident: scoping, containment, forensics and the report afterwards. Suits L2 and L3 analysts who like the hard tickets and stay calm when things are on fire.
- What it takes
- Usually one to three years in a SOC plus solid Windows and Linux forensics. Some teams expect on-call rotations.
- First step
- Volunteer to write the timeline for the next confirmed incident your team handles, and ask the lead to review it.
Threat intelligence analyst
Tracks attacker groups and techniques, then turns that into briefings and detections your team can use. Suits analysts who read threat reports for fun and write well.
- What it takes
- SOC experience and fluency with MITRE ATT&CK. Strong writing is the real filter in interviews.
- First step
- Write a one-page brief on a threat group targeting your industry and map its techniques to what your SOC can actually see.
Detection engineer
Writes and tunes the rules the SOC runs on, often as code with testing and version control. Suits analysts who keep saying "this alert is noisy, I could fix it."
- What it takes
- Query language skill (SPL, KQL or similar), some Python, and comfort with Git. Most people get in through an internal move.
- First step
- Take the noisiest rule in your queue this week, write down why it misfires, and propose a tuned version to your lead.
Cloud security analyst or engineer
Secures AWS, Azure or Google Cloud: identity and access, logging, misconfiguration findings and guardrails. Suits analysts who already chase cloud alerts and want to fix the causes.
- What it takes
- Hands-on time in at least one cloud. A provider security certification helps, and a free-tier lab account costs little.
- First step
- Open a free-tier account in the cloud your company uses and turn on its audit logging, then look at what a login event records.
Penetration tester
Attacks systems with permission and reports what could be exploited. Suits analysts who enjoy the attacker side of investigations. Entry roles are competitive and usually want proof of hands-on skill.
- What it takes
- Months of practice on legal lab platforms, and often a hands-on offensive certification. Expect a practical exam or take-home in interviews.
- First step
- Work through five beginner machines on a legal practice platform and write a short report for each, as if for a client.
Security engineer
Builds and runs the security tooling: EDR, SIEM pipelines, identity, email security. Suits analysts who like fixing the platform more than working the queue.
- What it takes
- Scripting and systems administration skills. CISSP is common in senior postings and requires five years of experience in two or more of its eight domains, per ISC2 (an Associate path exists).
- First step
- Ask your engineering team for one small tooling task, like a log source onboarding, and document what you did.
Specific moves, step by step
What carries over, what to build, a 90-day plan and your résumé rewritten for each one.
Sample conversation
How a conversation with Carmen starts
Carmen asks before she suggests. An illustrative example, not a real person.
Two years as an L1. I'm tired of the queue and everyone says go GRC.
Two years of triage is useful in GRC, you have seen controls fail. Which tickets did you actually enjoy closing?
The ones where I had to write up what happened and why a control missed it.
That writing is most of GRC work. Want to map your SOC experience against a GRC analyst posting and see what is missing?
Work it out with Carmen, free
30 free minutes with Carmen and the team. No card needed.
Questions & answers
- Is moving from SOC to GRC a step down?
- No. It is a different track, with more focus on risk, audits and policy and less on live alerts. GRC analysts who understand how attacks really work are valued, and the path leads to risk management and security leadership.
- What is the typical SOC analyst career path?
- Many people start in IT support or help desk, move into an L1 SOC role, then L2 and L3. From there they specialize: incident response, detection engineering, threat intelligence, cloud security, GRC or security engineering.
- How long should I stay in the SOC before moving?
- There is no fixed number. Most specialties want you to have handled real incidents and know your tools well. When your questions start being about why things happen rather than how to close the ticket, you are usually ready to look.
- Which certification should I get to leave the SOC?
- Match it to the role you want. Security+ is a common baseline (CompTIA recommends Network+ and two years in a security or systems administrator role first). CISSP and CISA both require five years of experience. Check real postings for the role you want before paying for anything.
More for security analysts
Change careers
Sources
- BLS Occupational Outlook Handbook: Information Security Analysts
- ISACA: Get CISA certified
- ISC2: CISSP experience requirements
- CompTIA: Security+ (V7)
Last checked September 29, 2026.